PC Ekspert Forum

PC Ekspert Forum (https://forum.pcekspert.com/index.php)
-   Operativni sustavi (https://forum.pcekspert.com/forumdisplay.php?f=36)
-   -   Linux OS - info, how-to, pitanja, novosti, savjeti, problemi... (https://forum.pcekspert.com/showthread.php?t=234127)

tomek@vz 21.03.2025. 19:03

Ala nam je Bubba elokventan :D

https://www.youtube.com/watch?v=vXk_OpRYnwg

medo 21.03.2025. 20:14

Vrijeme je za AI scraper IP blacklistu ako već ne postoji :kafa:

tomek@vz 22.03.2025. 19:08

Citiraj:

Two "groundbreaking research reports" on open source security were announced this week by the Linux Foundation in partnership with the Open Source Security Foundation (OpenSSF) and Linux Foundation Europe. The reports specifically address the EU's Cyber Resilience Act (or CRA) and "highlight knowledge gaps and best practices for CRA compliance."

"Unaware and Uncertain: The Stark Realities of CRA-Readiness in Open Source" includes a survey which found that when it comes to CRA requirements, 62% of respondents were either "not familiar at all" (36%) or "slightly familiar" (26%) — while 51% weren't sure about its deadlines. ("Only 28% correctly identified 2027 as the target year for full compliance," according to one infographic, which adds that CRA "is expected to drive a 6% average price increase, though 53% of manufacturers are still assessing pricing impacts.") Manufacturers, who bear primary responsibility, lack readiness — many [46%] passively rely on upstream security fixes, and only a small portion produce Software Bills of Materials (SBOMs). The report recommends that manufacturers take a more active role in open source security, that more funding and legal support is needed to support security practices, and that clear regulatory guidance is essential to prevent unintended negative impacts on open source development.
The research also provides "an in-depth analysis of how open collaboration can strengthen software security and innovation across global markets," with another report that "examines how three Linux Foundation projects are meeting the CRA's minimum compliance requirements" and "provides insight on the elements needed to ensure leadership in cybersecurity best practices." (It also includes CRA-related resources.)

"These two reports offer actionable conclusions for open source stakeholders to ready themselves for 2027, when the CRA comes into force," according to a Linux Foundation reserach executive cited in the announcement. "We hope that these reports catalyze higher levels of collaboration across the open source community."

Ivo_Strojnica 23.03.2025. 10:49

Citiraj:

Autor tomek@vz (Post 3795188)
Ala nam je Bubba elokventan :D

https://www.youtube.com/watch?v=vXk_OpRYnwg

Smiren i pristojan, pravi profic. :chears:

Bubba 24.03.2025. 19:39

Citiraj:

Autor tomek@vz (Post 3795188)
Ala nam je Bubba elokventan :D

https://www.youtube.com/watch?v=vXk_OpRYnwg

Citiraj:

Autor Ivo_Strojnica (Post 3795373)
Smiren i pristojan, pravi profic. :chears:

Ove godine dolazi i jubilarni 30. DORS!

https://www.dorscluc.org/

PS za 2026. se borimo za još neke događaje koji su na svjetskom nivou, pa da ih malo iz prosinca ove godine u Tokiju stavimo nekada kroz 2026. u Zagreb ;)

Dottore 24.03.2025. 19:51

Nekako si smršo?

Bubba 24.03.2025. 19:59

Citiraj:

Autor Dottore (Post 3795647)
Nekako si smršo?

Ubio me oupen sours.

tomek@vz 24.03.2025. 20:47

Citiraj:

Autor Bubba (Post 3795650)
Ubio me oupen sours.


:lol2:

Cuky 24.03.2025. 20:49

Citiraj:

Autor Bubba (Post 3795650)
Ubio me oupen sours.

Il ovaj voditelj kojem se vidi da mu ne lezi tematika 🤣

tomek@vz 26.03.2025. 05:25

Ovo sad zbilja vec prelazi svaku granicu dobrog ukusa.


Citiraj:

Software developer Xe Iaso reached a breaking point earlier this year when aggressive AI crawler traffic from Amazon overwhelmed their Git repository service, repeatedly causing instability and downtime. Despite configuring standard defensive measures -- adjusting robots.txt, blocking known crawler user-agents, and filtering suspicious traffic -- Iaso found that AI crawlers continued evading all attempts to stop them, spoofing user-agents and cycling through residential IP addresses as proxies. Desperate for a solution, Iaso eventually resorted to moving their server behind a VPN and creating "Anubis," a custom-built proof-of-work challenge system that forces web browsers to solve computational puzzles before accessing the site. "It's futile to block AI crawler bots because they lie, change their user agent, use residential IP addresses as proxies, and more," Iaso wrote in a blog post titled "a desperate cry for help." "I don't want to have to close off my Gitea server to the public, but I will if I have to."

Iaso's story highlights a broader crisis rapidly spreading across the open source community, as what appear to be aggressive AI crawlers increasingly overload community-maintained infrastructure, causing what amounts to persistent distributed denial-of-service (DDoS) attacks on vital public resources. According to a comprehensive recent report from LibreNews, some open source projects now see as much as 97 percent of their traffic originating from AI companies' bots, dramatically increasing bandwidth costs, service instability, and burdening already stretched-thin maintainers.

Kevin Fenzi, a member of the Fedora Pagure project's sysadmin team, reported on his blog that the project had to block all traffic from Brazil after repeated attempts to mitigate bot traffic failed. GNOME GitLab implemented Iaso's "Anubis" system, requiring browsers to solve computational puzzles before accessing content. GNOME sysadmin Bart Piotrowski shared on Mastodon that only about 3.2 percent of requests (2,690 out of 84,056) passed their challenge system, suggesting the vast majority of traffic was automated. KDE's GitLab infrastructure was temporarily knocked offline by crawler traffic originating from Alibaba IP ranges, according to LibreNews, citing a KDE Development chat. While Anubis has proven effective at filtering out bot traffic, it comes with drawbacks for legitimate users. When many people access the same link simultaneously -- such as when a GitLab link is shared in a chat room -- site visitors can face significant delays. Some mobile users have reported waiting up to two minutes for the proof-of-work challenge to complete, according to the news outlet.


Bubba 27.03.2025. 17:24

Citiraj:

Autor Cuky (Post 3795665)
Il ovaj voditelj kojem se vidi da mu ne lezi tematika 🤣

Ti si fotorobot one dobre stare ispalio - ostao živ.

tomek@vz 27.03.2025. 18:46

Citiraj:

Despite the minor delay, Linux 6.14 arrives packed with cutting-edge features and improvements to power upcoming Linux distributions, such as the forthcoming Ubuntu 25.04 and Fedora 42. The big news for desktop users is the improved NTSYNC driver, especially those who like to play Windows games or run Windows programs on Linux. This driver is designed to emulate Windows NT synchronization primitives. What that feature means for you and me is that it will significantly improve the performance of Windows programs running on Wine and Steam Play. [...] Gamers always want the best possible graphics performance, so they'll also be happy to see that Linux now supports recently launched AMD RDNA 4 graphics cards. This approach includes support for the AMD Radeon RX 9070 XT and RX 9070 graphics cards. Combine this support with the recently improved open-source RADV driver and AMD gamers should see the best speed yet on their gaming rigs.

Of course, the release is not just for gamers. Linux 6.14 also includes several AMD and Intel processor enhancements. These boosts focus on power management, thermal control, and compute performance optimizations. These updates are expected to improve overall system efficiency and performance. This release also comes with the AMDXDNA driver, which provides official support for AMD's neural processing units based on the XDNA architecture. This integration enables efficient execution of AI workloads, such as convolutional neural networks and large language models, directly on supported AMD hardware. While Rust has faced some difficulties in recent months in Linux, more Rust programming language abstractions have been integrated into the kernel, laying the groundwork for future drivers written in Rust. [...] Besides drivers, Miguel Ojeda, Rust for Linux's lead developer, said recently that the introduction of the macro for smart pointers with Rust 1.84: derive(CoercePointee) is an "important milestone on the way to building a kernel that only uses stable Rust functions." This approach will also make integrating C and Rust code easier. We're getting much closer to Rust being grafted into Linux's tree.

In addition, Linux 6.14 supports Qualcomm's latest Snapdragon 8 Elite mobile processor, enhancing performance and stability for devices powered by this chipset. That support means you can expect to see much faster Android-based smartphones later this year. This release includes a patch for the so-called GhostWrite vulnerability, which can be used to root some RISC-V processors. This fix will block such attacks. Additionally, Linux 6.14 includes improvements for the copy-on-write Btrfs file system/logical volume manager. These primarily read-balancing methods offer flexibility for different RAID hardware configurations and workloads. Additionally, support for uncached buffered I/O optimizes memory usage on systems with fast storage devices.
Linux 6.14 is available for download here.

medo 27.03.2025. 22:42

Citiraj:

Autor tomek@vz (Post 3795947)
Ovo sad zbilja vec prelazi svaku granicu dobrog ukusa.


Mislim da se nikada još nije dogodilo da je nešto toliko opterećivalo web na globalnoj razini.

medo 28.03.2025. 16:02

Stavio sam Ubuntu 25.04 betu na stroj sa 9600X CPUom budući da 6.14 kernel ima fuckload patcheva za Zen 5 u odnosu na 6.11

Bio je to pucanj u prazno budući da su mi se VMovi u Qemu stalno rušili. do-release-upgrade sa 24.10 i… uspjelo je! Radi :)

Installer se malo zblesirao jer je snapd bio purge-an na postojećoj instalaciji ali nakon updatea initramfs i gruba rebootao se normalno.

c-shadow 28.03.2025. 16:21

Kako su krenuli još malo pa će snap na ubuntu biti obavezan i neće htjeti raditi bez toga :D

medo 28.03.2025. 16:45

fwupdmgr je u snapu na Ubuntu :-/

tomek@vz 29.03.2025. 07:14

Citiraj:

Autor medo (Post 3796547)
fwupdmgr je u snapu na Ubuntu :-/


https://flathub.org/apps/org.freedesktop.fwupd


Native > Source build > Flathub > Appimage >>>>> Snap


Za Desktop:


Fedora/Debian > Mint > OpenSuse TW > > > > ....shity distros >>> Ubuntu (trenutno).



To snap sranje je tolko sporo da boli glava (a i aplikacije instalirane na taj nacin) a Canonical to toliko forsira da je naporniji od pizdarija koje MS gura kroz Win11.

tomek@vz 29.03.2025. 15:08

A kad smo vec kod toga...


Citiraj:

New Ubuntu Linux security bypasses require manual mitigations
Citiraj:


  1. Bypass via aa-exec: Users can exploit the aa-exec tool, which allows running programs under specific AppArmor profiles. Some of these profiles - like trinity, chrome, or flatpak - are configured to allow creating user namespaces with full capabilities. By using the unshare command through aa-exec under one of these permissive profiles, an unprivileged user can bypass the namespace restrictions and increase privileges within a namespace.
  2. Bypass via busybox: The busybox shell, installed by default on both Ubuntu Server and Desktop, is associated with an AppArmor profile that also permits unrestricted user namespace creation. An attacker can launch a shell via busybox and use it to execute unshare, successfully creating a user namespace with full administrative capabilities.
  3. Bypass via LD_PRELOAD: This technique leverages the dynamic linker’s LD_PRELOAD environment variable to inject a custom shared library into a trusted process. By injecting a shell into a program like Nautilus - which has a permissive AppArmor profile - an attacker can launch a privileged namespace from within that process, bypassing the intended restrictions.

Citiraj:

In a bulletin published on the official discussion forum (Ubuntu Discourse), the company shared the following hardening steps that administrators should consider:
  • Enable kernel.apparmor_restrict_unprivileged_unconfined=1 to block aa-exec abuse. (not enabled by default)
  • Disable broad AppArmor profiles for busybox and Nautilus, which allow namespace creation.
  • Optionally apply a stricter bwrap AppArmor profile for applications like Nautilus that rely on user namespaces.
  • Use aa-status to identify and disable other risky profiles.

-> Link

tomek@vz 02.04.2025. 16:04

Citiraj:

A persistent Linux malware known as “Outlaw” has been identified leveraging unsophisticated yet effective techniques to maintain a long-running botnet.


Outlaw follows a structured multi-stage infection process:
  1. Initial Access: The malware gains entry through SSH brute-forcing, targeting systems with weak or default credentials. A component called “blitz” handles these brute-force attacks by retrieving target lists from a command-and-control (C2) server.
  2. Payload Deployment: Once access is gained, the malware downloads and executes a package containing scripts and binaries. The primary dropper script, tddwrt7s.sh, initiates the infection chain by deploying components into hidden directories.
  3. Persistence Mechanisms: Outlaw establishes persistence through cron jobs and SSH key manipulation. It injects attacker-controlled SSH keys into compromised systems while locking configuration files to prevent tampering.
  4. Propagation: The malware acts as a worm, spreading laterally within local subnets by launching additional SSH brute-force attacks from infected hosts. This self-replication ensures rapid expansion of the botnet.


> gbhackers


https://blogger.googleusercontent.co...erview%20.webp

kopija 04.04.2025. 17:26

Naletio na ovu vijest prije par tjedana ali nije mi se činilo vrijedno repostati.
Još jedna u nizu dobrih želja koje ne prežive susret s surovom stvarnošću, pomislih.
Al sad se EU prijeti odmazdom američkim korporacijama nakon Trumpove objave carinskog rata.
Citiraj:

Taking 16% of an estimated 2025 total employment figure of around 200 million (a reasonable projection based on the 199 million in 2023 and ongoing recovery from the pandemic), this would suggest approximately 32 million public service workers in the EU as of today, April 4, 2025.
Znači minimalno 64 miliona Windows/Office licenci samo za javni sektor.
Bogme bi ih to lupilo tam gdje boli.
Naravno, treba imat muda za pokazat Trumpu srednji prst.

tomek@vz 04.04.2025. 19:43

Citiraj:

Autor kopija (Post 3797747)
Naletio na ovu vijest prije par tjedana ali nije mi se činilo vrijedno repostati.
Još jedna u nizu dobrih želja koje ne prežive susret s surovom stvarnošću, pomislih.
Al sad se EU prijeti odmazdom američkim korporacijama nakon Trumpove objave carinskog rata.
Znači minimalno 64 miliona Windows/Office licenci samo za javni sektor.
Bogme bi ih to lupilo tam gdje boli.
Naravno, treba imat muda za pokazat Trumpu srednji prst.


Da ima pravde - da - ali ne vjerujem. Ljudi su stvorenja navike. Da se odreknu MS i Apple-a? Nikad pa ni onda. 100% ce se dogovoriti s vremenom oko tarifa.

Libertus 04.04.2025. 20:11

Nisu problem tarife nego neovisnost. Nekako sumnjam da će to zaživjeti, tj. da će EU to izgurati do kraja, ali nadam se da sam u krivu.

c-shadow 04.04.2025. 21:00

Firefox 137 changelog:
Code:

Support HEVC playback on Linux.

tomek@vz 05.04.2025. 07:56

Citiraj:

Sven Peter who remains one of the very active Asahi Linux developers and working on upstreaming various elements of Apple Silicon support for the Linux kernel has sent up warning flares around the eventual Apple M4 support.

Sven Peter posted on Mastodon this morning that it looks like the Apple M4 hardware enablement for Linux will be a "rather painful" affair due to changes compared to the Apple M1/M2 handling.

https://www.phoronix.net/image.php?i...ple_m4_painful


> Phoronix

tomek@vz 06.04.2025. 20:51

Citiraj:

Linux 6.15 Performance Events Adds Support For AMD Zen 5 Load Latency Filtering

> Phoronix


Citiraj:

Linux 6.15 Crypto Subsystem Delivers Faster AES-CTR For AMD Zen 5 & Other x86_64 CPUs


> Phoronix


Citiraj:

Nvidia engineer breaks and then quickly fixes AMD GPU performance in Linux


> Tom's Hardware

Dottore 07.04.2025. 13:13

Kad kreće ubuntu 25.04?

Mommistake 07.04.2025. 13:28

Citiraj:

Autor Dottore (Post 3798175)
Kad kreće ubuntu 25.04?

Sredinom mjeseca ja mislim da su confirmali.

tomek@vz 07.04.2025. 13:31

Citiraj:

Autor Dottore (Post 3798175)
Kad kreće ubuntu 25.04?


Meh, zaobidi u sirokom luku.

tomek@vz 07.04.2025. 17:38

Citiraj:

Linux GPU Control Application (LACT) continues being one of the best ways to control your AMD, NVIDIA or Intel GPU on a Linux system with version 0.7.3 out now with new features and improvements.
The first big one is that the charts window is now fully configurable. This means you can set whatever stats to show that you want, add and remove charts and much more. It's a nice quality of life improvement for the app.


https://uploads.golmedia.net/uploads...028278gol1.png

> GamingOnLinux

Dottore 07.04.2025. 19:50

Citiraj:

Autor tomek@vz (Post 3798178)
Meh, zaobidi u sirokom luku.


Kaj bilo? Koristim 24.04.2 LTS


Sva vremena su GMT +2. Sada je 23:10.

Powered by vBulletin®
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.
© 1999-2024 PC Ekspert - Sva prava pridržana ISSN 1334-2940
Ad Management by RedTyger